Apps April 22th 2021

New Facebook security flaw exposes emails of millions of users

April 22th 2021

Shortly after being the victim of a hacker who leaked data from more than 500 million users Facebook, the social network, now has to face a new security flaw that could harm the lives of many of its 2,8 billion users. A researcher discovered a front-end vulnerability in the application and, on top of it, created a tool that could cause real damage to those who use the social network.

Called Facebook Email Search v1.0, the tool can link up to 5 million email addresses to Facebook user accounts. The person responsible for discovering the new vulnerability has not been named, but in a statement to Ars Technica website, revealed that he had tried to warn those responsible for Mark Zuckerberg's company before actually leaking the problem publicly.

“I believe it is a very dangerous vulnerability, and I would like to help prevent it,” he simplified, after having released a video exposing the problem, and assured that, when he sought Facebook, he received as a response that the company did not think the exploit was “important enough to be fixed”.

The new flaw

The leaker responsible by the leak detailed how he discovered the Facebook security flaw and the process he went through to discover millions of email addresses and their respective users on the platform. “As you can see from the output log here, I’m getting a significant amount of results from them,” the researcher said as the video showed the tool processing the list of addresses. “I spent maybe $10 to buy over 200 Facebook accounts. And in three minutes, I was able to do that for 6.000 [email] accounts,” he said, as shown in the image below.

Image shows security flaw that allowed the leak of emails linked to the accounts of millions of Facebook users

Reproduction / Ars Technica

“So what I’d like to demonstrate here is an active vulnerability in Facebook that allows malicious users to query email addresses within Facebook and have Facebook return any matching users. It’s currently being used to compromise Facebook accounts with the goal of taking over groups of Facebook pages and advertising accounts for, obviously, monetary gain. Not only is this a major privacy violation, but it will result in another, larger data dump, including emails, that will allow unintended parties to gain access to personal data like phone numbers and more. I’m excited to demonstrate the front-end vulnerability so you can see how it works,” he added.

Reply from Facebook

After saying the flaw was “not important,” Facebook has since acknowledged the error and admitted that the vulnerability could indeed compromise users’ security. “It appears we mistakenly closed this bug bounty report before forwarding it to the appropriate team. We appreciate the researcher sharing their information and are taking initial steps to mitigate this issue while we continue to follow up to better understand their findings,” a spokesperson for Mark Zuckerberg’s team said.

This is just one of many security flaws that Facebook has been reporting lately. Earlier this month, security expert Ahmad Talahmeh revealed that he had discovered a bug that allowed attackers to delete lives (live broadcasts) from the platform without the account owner knowing.

The researcher explained that the vulnerability allowed live videos to be deleted as if the action had been done by the page owner. In reality, the error causes the video to have its duration cut to five milliseconds, according to Talahmeh. “Cutting the video to five milliseconds will make it 0 seconds long and the owner will not be able to undo it,” said the expert. The error was identified and promptly corrected by Facebook, which will now have yet another security flaw to try to fix.

Through which channels you reach those people, classic and out of the box. Apple Insider

Image: Gerd Altmann/Pixabay/CC

Read too